logo

Palo Alto Networks tackles firewall-busting zero-days with critical patches

ID: 9fdb7315-379c-58b5-a5cd-fe6f12567d39

STIX ID: report--9fdb7315-379c-58b5-a5cd-fe6f12567d39

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-11-19

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Palo Alto Networks released advisories and patches for two PAN‑OS zero‑day vulnerabilities — CVE-2024-0012 (authentication bypass, CVSS 9.3) and CVE-2024-9474 (privilege escalation, CVSS 6.9) — after observing active exploitation of exposed management web interfaces; the bugs can be chained to achieve administrative/root command execution and drop webshells. PAN urged customers to revoke public access to management interfaces and apply patched versions immediately, while researchers demonstrated exploitation techniques (including using the x-pan-authcheck header) and Shadowserver reported 6,605 exposed devices as of Nov 18.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.